8 October 2026 by ASC Team
Implement ISO 45001 in the order the clauses feed each other. Start with a gap assessment and a legal register, because the law applies today. Get top management’s commitment and the consultation and participation process running early, because workers have to take part in what follows. Then identify hazards and assess risks with the people who do the work, choose controls from the top of the hierarchy, set objectives, and control contractors, change and emergencies. Finish with monitoring, compliance evaluation, internal audit and management review, and run the system long enough to produce real records before you book a certification audit.
What does implementing ISO 45001 involve?
It means turning a safety file into a safety system. Most South African sites I work with start with a lever arch file: a baseline risk assessment by a consultant, appointment letters, certificates and training registers. ISO 45001:2018 asks for the processes that keep those true. The standard in force is ISO 45001:2018 as amended by Amendment 1:2024.
| Phase | Clauses | What you produce | Who owns it |
|---|---|---|---|
| 1. Find the gaps | All, and 6.1.3 | Gap assessment; first legal register | SHEQ lead |
| 2. Set direction | 4.1 to 4.4, 5.1 to 5.3 | Context and climate change decision, scope, policy, roles | Top management |
| 3. Bring workers in | 5.4 | Consultation and participation process, representatives, committee | Top management and representatives |
| 4. Plan | 6.1, 6.2 | HIRA register, opportunities, legal register, objectives | Area managers with workers |
| 5. Support and operate | 7, 8 | Competence, awareness, communication, controls, change, contractors, emergencies | Line managers |
| 6. Check | 9 | Monitoring, compliance evaluation, internal audit, management review | SHEQ lead and top management |
| 7. Improve | 10 | Incident investigation and corrective action, improvement | Everyone |
What are the steps to implement ISO 45001, in order?
- Run a gap assessment. Take every requirement as a line, record what exists, and mark it in place, partly in place or missing, with the evidence. On the case site we use in our courses, Mzansi Fresh Meals in Kempton Park, it showed in an afternoon that the policy was a 2019 page nobody had seen, there was no OH&S legal register, the committee had not met since February 2026, and nothing existed for internal audit or management review. The case is a training scenario built from real audit patterns; no real company is named.
- Build the legal register first. The OHS Act applies now, certified or not. Clause 6.1.3 requires you to determine the legal requirements that apply to your hazards and how they apply. Start from the hazards: the chemical store pulls in the Regulations for Hazardous Chemical Agents, the boiler the Pressure Equipment Regulations, a building project the Construction Regulations, 2014. Use current law: the Noise Exposure Regulations, 2024 and the Physical Agents Regulations, 2024 have replaced the older regulations.
- Get top management to own it. Clause 5.1 lists thirteen things top management shall do, from taking overall responsibility to supporting the health and safety committee. In law, section 16(1) of the OHS Act already puts the duty on the chief executive officer. A monthly steering meeting chaired by the MD is the simplest proof.
- Record context, interested parties and scope. Clause 4.1 asks for the issues that affect your OH&S outcomes, and since Amendment 1:2024 a determination of whether climate change is a relevant issue. Clause 4.2 asks who the interested parties are and which of their needs are, or could become, legal requirements. Clause 4.3 says the system shall include the activities within your control or influence that can affect OH&S performance, so put contractors and projects inside the scope.
- Set up consultation and participation. Clause 5.4 requires a process at all applicable levels and functions, with obstacles and barriers removed. On a South African site start with sections 17 to 20 of the OHS Act: representatives designated where there are more than 20 employees, at least one for every 50 or part of 50 outside shops and offices, and a committee meeting at least once every three months. Then reach the night shift, the agency staff and the contractors.
- Write the policy. Clause 5.2 requires commitments to safe and healthy working conditions, a framework for objectives, fulfilling legal requirements, eliminating hazards and reducing risks, continual improvement, and consultation and participation of workers. Consult non-managerial workers on it, as 5.4 d) 2) emphasises.
- Identify hazards and assess risks with the workers. Clause 6.1.2.1 lists what hazard identification takes into account, from how work is organised to changes in knowledge. Rate each risk with the existing controls as they actually perform, as 6.1.2.2 a) requires. The companion guide on HIRA registers walks this line by line.
- Choose controls down the hierarchy. Clause 8.1.2: eliminate, substitute, engineering controls and reorganisation of work, administrative controls including training, then adequate PPE. Section 8(2)(b) of the OHS Act already asks you to eliminate or reduce a hazard before resorting to PPE.
- Set objectives and plan them. Clause 6.2 asks for objectives that are measurable if practicable, monitored and communicated, with plans that say what, with what resources, who, by when, how results are evaluated and how actions fit into business processes.
- Control operations, change, contractors and emergencies. Competence and awareness under 7.2 and 7.3; operational criteria under 8.1.1; management of change under 8.1.3; procurement, contractors and outsourcing under 8.1.4; and an emergency process under 8.2 tested on every shift.
- Measure, evaluate compliance, audit and review. Clause 9.1.1 asks what you monitor and how; 9.1.2 asks you to evaluate compliance with the legal register at a set frequency; 9.2 asks for an internal audit programme that includes consultation and reports relevant results to workers; 9.3 asks top management to review the system against inputs a) to g) and communicate the relevant outputs to workers.
- Investigate and improve. Clause 10.2 requires incidents and nonconformities to be investigated with the participation of workers, causes determined, similar cases checked, risk assessments reviewed and effectiveness confirmed. On a South African site the same process carries the section 24 report, the General Administrative Regulations recording and seven day investigation, and the COID Act report within seven days.
How long does ISO 45001 implementation take?
It depends on the size of the site and how much already works. The case site’s board set a plan of about twelve months to a certification stage 2 in November 2027, with twelve consultant days, an occupational hygiene survey, audiometry and medical surveillance in the budget, a SHEQ officer with three days a week for the project, and a monthly steering meeting chaired by the managing director. For a site of 400 people with one SHEQ officer, that is realistic but not slack.
What takes longest is rarely the documents. It is getting representatives elected for every area and shift, getting hazard identification done with the people on the floor, and producing enough months of records for an auditor to see a running system.
Who does the work, and what must top management do?
The SHEQ lead runs the project. Area managers own the HIRA lines, the controls and the objectives in their areas. Representatives and workers take part in hazard identification, control selection and investigations, which clause 5.4 e) emphasises. Top management does what clause 5.1 says only top management can do: take overall responsibility, provide resources, promote the culture, protect workers from reprisals, and chair the review.
If the MD hands the whole thing to the SHEQ officer, the auditor will find out in the first interview. I have seen a stage 2 go badly in the first half hour because the managing director could not name the site’s three highest risks.
What slows an ISO 45001 implementation down?
- A generic baseline risk assessment. A consultant’s register of 212 lines from 2021, never reviewed, with no task based assessments, tells an auditor that hazard identification is not ongoing.
- Participation on paper. Representatives listed, committee minutes from last year, and no voice at all for the night shift or the agency staff.
- Investigations that blame people. “Operator did not follow procedure” is where an investigation stopped, not a cause.
- A legal register copied from a list. No column saying how anything applies on the site, and repealed regulations still on it.
- Controls stuck at the bottom of the hierarchy. A sign, a toolbox talk and PPE where an engineering control was plainly available.
What do certification auditors look for at stage 1 and stage 2?
The two stage audit is certification body practice, not a requirement of ISO 45001. At stage 1 the auditor usually reviews the documented information, the scope, the legal register, the HIRA approach and whether internal audit and management review have happened. At stage 2 she tests implementation on the floor: worker interviews on 7.3, the permits and lockout, the contractor file, the incident trail, the night shift. Certification bodies generally expect a complete internal audit cycle and a management review before stage 2. Accredited bodies work to ISO/IEC 17021-1, which defines major and minor nonconformities and sets surveillance audits at least once a calendar year in the three year cycle.
Choose a certification body accredited for ISO 45001 by SANAS, South Africa’s national accreditation body, or by another Global ACI (formerly IAF) signatory such as UKAS, and check the body and its scope on IAF CertSearch. And remember that the auditor is not the inspector. A Department of Employment and Labour inspector enforces the OHS Act whatever the certificate says.
Frequently asked questions
Can we implement ISO 45001 without a consultant?
Yes, if someone on site has the time and the competence. The standard does not require a consultant. Many sites use a few consultant days for the gap assessment and a pre-audit, and build the rest themselves.
Do we need an OH&S manual?
No. ISO 45001 requires specific documented information, such as the scope, the policy, the legal requirements, the objectives and plans, and evidence of competence, monitoring, audits, reviews and incidents. It does not require a manual or a set of mandatory procedures.
Should we wait for ISO 45001:2027?
No. Voting on the draft, ISO/DIS 45001, closed on 9 September 2026, and ISO expects the new edition in the first half of 2027. No transition period has been set; certification bodies expect three years, as was set for ISO 9001:2026, and a 2018 certificate stays valid during the transition. A system built to ISO 45001:2018 with Amendment 1:2024 is the right base, and the law you have to meet does not wait.
Can we integrate ISO 45001 with ISO 9001 and FSSC 22000?
Yes. ISO 45001 shares its structure with ISO 9001 and ISO 14001, so context, audits, review and improvement can run as one set of processes. Keep worker participation, hazard identification and the hierarchy of controls whole.
Who should lead the implementation?
A SHEQ manager or officer with authority and time, reporting to a member of top management, usually the section 16(2) assignee for the site. The MD chairs the steering meeting.
Do agency workers and contractors have to be in the system?
Yes. They are workers under clause 3.3, and clause 4.3 requires the system to include activities within your control or influence. Agency labour is externally provided labour managed under 8.1.4.1 and 8.1.4.3, and for the OHS Act, which excludes the labour broker from the definition of employer, agency staff working under your direction are your employees under section 8.
Which ASC course takes you through ISO 45001 implementation?
This guide is drawn from ISO 45001:2018 Understanding and Implementation, FS62, for the SHEQ manager, safety officer, ISO 9001 or ISO 14001 coordinator or consultant who has to build the system.
R3 950, prices in rand with no VAT added. About 20 hours, self paced, lifetime access.
- Every clause of ISO 45001:2018 at implementation depth, with the South African law mapped to it.
- Eight tools, from the ISO 45001 Gap Assessment to the OH&S Management Review Pack Builder, exported as one implementation workbook.
- 64 case packs; the tools carry the Mzansi ready meals plant, and the lessons give a citrus packhouse and a restaurant group as workshop variants.
- A three sitting workshop with timed practical stages and a video proctored final, all at 70 percent.
Your managing director should take ISO 45001 Management Awareness, R1 295, and the floor Introduction to ISO 45001:2018, R1 195.
Enrol now and start building your system today. See all eight courses at ISO 45001 training. Not sure it fits? WhatsApp ASC.
Related guides: Hazard identification and risk assessment under ISO 45001 and The OHS Act and ISO 45001: the legal duties a management system has to carry.
Sources
- ISO 45001:2018, Occupational health and safety management systems: Requirements with guidance for use (ISO), and ISO 45001:2018/Amd 1:2024, Climate action changes
- Occupational Health and Safety Act 85 of 1993
- General Administrative Regulations, 2003; Regulations for Hazardous Chemical Agents (GN R280 of 2021); Noise Exposure Regulations, 2024; Physical Agents Regulations, 2024; Pressure Equipment Regulations, 2009; Construction Regulations, 2014
- Compensation for Occupational Injuries and Diseases Act 130 of 1993
- ISO, ISO/DIS 45001 project page, iso.org; DNV on the transition, africa.dnv.com; LRQA on ISO 9001:2026, lrqa.com
- IAF CertSearch, iafcertsearch.org
ISO 45001 is copyright and is not reproduced here. ASC is not affiliated with ISO. Last updated 8 October 2026.